Fraud signals and limits
flags, never silent rejections.
Every payout request is checked against limits that refuse it and fraud signals that flag it. Flags never reject a request on their own: they make it wait for a person and show you why.
01What refuses a request
requestPayout refuses a request with a reason token the app translates (docs/CONTRACT-4.0.md §11.3, firebase/functions/src/wallet/payouts.ts):
| Reason | Why |
|---|---|
disabled, method_off | The wallet or that method is switched off |
platform | The wallet is off on the user's platform (iOS and web by default) |
country | The method or gift card is limited to other countries |
bad_email, bad_asset, bad_address, missing_bank_field, bad_iban, bad_giftcard, bad_face_value, amount_mismatch | The destination does not pass the checks of that method |
below_min | Below the method's minimum, or the fee is as large as the amount |
insufficient_funds | More than the available balance |
account_age | Account younger than wallet.minAccountAgeDays (default 3) |
email_unverified | Not signed in with Google or Apple and no verified e-mail, while wallet.requireVerifiedEmail is on (default) |
negative_balance | A reversal made the available balance negative |
daily_limit, monthly_limit | Over the per-user limit for the UTC day or month (pending, approved, processing and paid requests count) |
banned, frozen | The user is banned, or you froze their payouts on the Wallets page |
rate_limited | More than 3 requests in an hour |
Troubleshooting for each: Payouts.
02Fraud flags on a request
A request that passes is checked once more and gets a list of flags (review.flags, fraudFlags() in firebase/functions/src/wallet/money.ts). The Payouts page shows them as pills.
| Flag | Raised when | What to check |
|---|---|---|
shared_device | The user's device has more accounts than Anti-fraud → Accounts per device | The other accounts in the drawer; one person farming several wallets |
emulator, rooted, vpn | The device reported it (device signals) | Context, not proof: many honest users run a VPN |
reversal_rate | Reversals are more than 20 % of the user's conversions in the last 30 days | The wallet entries: offers completed and then charged back |
velocity | 2 or more other requests in the last 24 hours | Splitting a big amount into small ones |
young_account | Account younger than 14 days | How the cash was earned so fast |
first_payout | The user has no paid request yet | Every first payout is reviewed by a person |
destination_shared | Another account used the same PayPal e-mail, crypto address, bank account or card | "Destination also used by" in the drawer |
user_flagged | The user has open fraud flags | Console → Fraud flags |
Device, emulator, root and VPN come from the device itself. A modified app can send anything. Use them to decide what to look at, together with the server-side facts (wallet entries, reversals, shared destinations, account age).
Destination reuse is tracked with a SHA-256 hash of the normalised destination (payoutDestinations, payoutRequests.destinationKey), so the console finds matches without keeping a second copy of the destination.
03Auto-approve
Console → Wallet & payouts → Auto-approve small requests (off by default). A request is auto-approved only when all three are true:
- auto-approve is on,
- the amount is at or below Always review requests above (cents) (default 2000),
- the request has no flag at all. Because every first payout is flagged
first_payout, a user's first payout is never auto-approved.
An auto-approved PayPal request is sent at once when PayPal credentials exist. Other methods still need you to pay and mark paid. Start with auto-approve off, review by hand for a few weeks, and only then consider it.
04Before the money reaches the wallet
- The hold keeps new cash pending for
wallet.holdDays(default 14) so provider reversals land before users can cash out (Hold). - Big cash credits and every credit of a flagged user wait in the Review queue (
fraud.offerwallHoldOverCents, details). - The 3.1 protection still applies: signed provider postbacks, de-duplication, App Check, the accounts-per-device limit and the velocity rule (Anti-fraud).
05Your own checks
- Keep daily and monthly limits that fit your budget; 0 means no limit
- Look at every flagged request before you approve it
- Freeze payouts for a user you are investigating (earning continues)
- Before a crypto payout, check the asset and network; transfers cannot be reversed
- Reconcile your PayPal, bank and wallet statements with the Business page regularly
- Apply the identity checks your obligations require before paying (KYC and AML); the app does not verify identities